While yes 2fa is a thing on Roblox and is immensely necessary, token hijacks still bypass it (at least when I last heard about it),
Two-step authentication is not bypassable. A token grants you authentication to ‘act’ as the account; however, with high-level action, it requires you to enter a code, which is used to authenticate the request. Think of it as your house, where your token is the house key. You can enter and leave your house with the key, but if you wish to sell your house, you need to provide identity documents and other materials that someone else cannot provide physically (unless they’ve dedicated years to forge your identity)
I believe someone was providing you with false information regarding it.
The point that I am trying to make is that no level of conscious effort to improve security can stop zero day attacks and unknown atttack vectors like that. Viruses and scams do not only affect the stupid, everyone will fall for one eventually. But provided you do not share the pin, it ensures your account is secure.
Also, zero-days are not exclusive to Roblox, a zero day in a program or the OS that users use can result in a virus getting onto the system and getting the login token (and its far from unheard of), which is primarily what I was referring to. Also, hijacking of other services, such as the creator of a mod for a game that allows mods to run scripts can result in malware on a system (something completely unavoidable and near impossible to be aware of in advance of the attack doing its job).
Understandable, however, this is outside the scope of ROBLOX. Legally, ROBLOX has no responsibility to provide security measures that it cannot directly prevent. The blame is put on the company responsible for allowing the vulnerability. However, ROBLOX have provided guidance and information on account safety, provided with prompts and general leaflets that are available online.
I can assure you ROBLOX is a safe platform. As you know, it is a platform filled with minors where data protection is critical, and unauthorised access can be catastrophic to the company.
I would also like to share why ROBLOX is doing so much about parental controls and safety. In Octoboer, a research report was made by Hindenburg (Roblox stock drops after Hindenburg Research short report) which dropped their stocks significantly and investors were selling. One of their points was how unsafe ROLOX was to children and the level of child exploitation there was on the platform.
As any company would do, they rushed to engineer products to ensure they have proportional protection in place, such as parental controls, for damage control. They’ve successfully done this, and have been able to increase their market value - otherwise, the ROBLOX board of directors might have voted in a new Chief Executive Officer.
industry standard when those are often flawed or not sufficient for many users (such as developers or other high-profile users) doesn’t help anyone,
In theory, these implementations are perfect and are appropriate for ROBLOX’s business model. As you know, Roblox has millions and millions of daily users a day and designing a convenient security system that is effective for every age group and demographic is important. We could apply certain identity checks, such as letters addressed in your name, to prove your identity (which financial institutions are required to check before opening an account) - however, that’s an inconvenience for the players.
Social engineering is unfortunately the most significant way unauthorised individuals access accounts, and this can only be prevented with education and general awareness. This affects every age group, and even businesses. These methods get smarter and smarter each day, and there isn’t much that we can do about it.
Roblox is not known for its ease of communication with a real human, so while yes, roblox could rollback any problems from a hijacker, the ability of an account owner to contact a human at Roblox let alone convince them to help them is much, much lower than the chance of an attack itself. (Note every instance of people only getting their accounts back after contacting a popular Roblox developer or content creator.
If you have a verified email on your account, and your email was changed, you can revert it with their page easily. However, it is up to individuals to have phone numbers, emails, and the necessary information on their account (excluding PII like billing information) to make a swift recovery. Sadly, ROBLOX isn’t required to investigate accounts without verifiable information to verify the creator, as anyone can make a request, and socially engineer their way in as discussed above.